Privacy Policy
Last updated: 31 August 2026
Short version: Kimo is built around phone numbers, so it has to be careful by default. We process the number you look up, your own number (on Android, to detect it; not on iOS), and only the contacts you choose to let us read — and we process them so the service works, not to build advertising profiles. Spam scores are community-driven and stored against the number, not against you. We do not sell your data.
This is the public Privacy Policy for Kimo. If you live in Türkiye, your rights under the KVKK are detailed below and override any less-protective statement here.
1. Who we are (the data controller)
Kimo (package com.nevranizamoglu.kimo) is made and operated by Nevra Nizamoğlu, based in Türkiye. We act as the data controller for the personal data described in this policy under the KVKK (the Turkish Personal Data Protection Law, 6698 sayılı Kanun), and as controller (or co-controller where required) under the GDPR for users in the EEA and the United Kingdom.
For any privacy question, complaint, or rights request, contact nevranizamoglu@gmail.com. We respond within 30 days at the latest.
2. What we collect and why
Kimo runs without an account. There is no email, no phone-number-as-identity, and no login. The data the app handles falls into a small number of buckets, each used only to deliver a specific feature:
3. Phone numbers you look up
When you type a Turkish phone number into the app, we send that number to our backend (a self-hosted PocketBase instance) and return whatever we know about it — a label, a community spam score, a category. We log the lookup event with a hashed, rotated, anonymous identifier for your device so we can enforce daily limits (e.g. ten free lookups a day on the free tier) and tell abuse patterns from genuine mistakes.
We never ask for or store your phone number as part of the lookup unless you look up your own number, which the app can detect automatically on Android.
4. Crowdsourced spam data
When a user reports a number as spam, the report is stored against the number, not the reporter. A report bundles the number, a category (e.g. insurance scam, sales call, market survey), an optional short note, the current community score, and a count. We do not attach the reporter's identity to a report.
If you would like your number hidden from Kimo's public record entirely, see §10.
5. Your own number (Android only)
On Android, the app asks for the phone state permission (READ_PHONE_STATE) only to read your own number, so you don't have to type it in and so the app can recognise when an incoming call is from yourself. We read the number once, on first launch, store a hash of it locally, and use it only to suppress the "is this you?" prompt. We do not transmit your own phone number to our backend.
iOS does not expose the device's own number through public APIs, so the iOS version never reads it.
6. Your address book (only if you grant access)
With your explicit consent, the app reads your address book so it can show you which numbers in a search result are already in your contacts versus unknown. We process the contact list on the device to produce this in-app overlay; your contacts are not uploaded to our backend in identifiable form. You can revoke this at any time in your device settings, and Kimo will continue to work for one-off lookups.
7. Call log (Android, deferred)
Kimo's Android manifest declares the call-log permission so a future version can mark unknown numbers directly in your recent-calls list. The current public release does not request or read the call log, and the permission is not used. We will update this section before any version that does.
8. Purchases
If you subscribe, payment is handled entirely by Apple or Google. We never see your card number, billing address, or full name on the receipt. We use RevenueCat to verify subscriptions across reinstalls — it receives an anonymous install identifier, the product identifier, transaction identifier and date, and your store country. We do not pass your name, email, or contacts to RevenueCat.
9. Analytics
The public release ships without third-party analytics. If we add analytics later, this section will be updated before they ship, and an in-app notice will announce the change.
10. Your rights (KVKK and beyond)
Depending on where you live, you have the right to:
- Learn what we hold about you and how we use it (Articles 11 of the KVKK; GDPR Art. 15).
- Have inaccurate data corrected (KVKK Art. 12; GDPR Art. 16).
- Have your data deleted where our legal basis no longer applies (KVKK Art. 7; GDPR Art. 17). For Kimo this means your lookup history and your hashed identifier.
- Stop direct marketing — we do not do direct marketing; this is automatic.
- Object to processing based on "legitimate interest" (GDPR Art. 21).
- Receive a portable copy of your data (GDPR Art. 20).
- Withdraw consent at any time, where processing is based on consent (KVKK Art. 7; GDPR Art. 7).
To exercise any of these, email nevranizamoglu@gmail.com with the address or number the request concerns. We will acknowledge within 30 days and complete the request or explain why a particular right does not apply.
If you want your phone number hidden from Kimo's public record: email us from a verifiable address with the number. We will add it to an internal suppression list; new spam reports against it will not be published, and existing score data for the number will be hidden.
Complaints. You also have the right to complain to the Kişisel Verileri Koruma Kurumu (Turkish Personal Data Protection Board, kvkk.gov.tr), or to your local supervisory authority under the GDPR.
11. Legal basis for processing
Where the KVKK or GDPR applies, our legal bases are:
- Service delivery: phone number lookups, spam scoring, daily-limit enforcement — based on the proper functioning of the Service (KVKK Art. 5/2-d; GDPR Art. 6/1-b).
- Spam-score publishing: based on the legitimate interest of Kimo users in knowing who is calling them (KVKK Art. 5/2-f; GDPR Art. 6/1-f). You can object at any time — see §10.
- Subscription verification: based on the performance of the subscription contract you accepted (KVKK Art. 5/2-c; GDPR Art. 6/1-b).
- Address-book overlay: based on your explicit consent, given in the iOS / Android permission dialog (KVKK Art. 5/1; GDPR Art. 6/1-a). You can withdraw it at any time.
12. International transfers
Kimo's primary backend lives in Türkiye. The third-party providers named in §14 process data globally — including the United States and the EEA — under their own standard contractual clauses or equivalent safeguards.
13. Security
- All network connections use HTTPS/TLS.
- Anonymous identifiers are hashed and rotated; we never link them to a phone number in storage.
- We never store payment information — Apple and Google handle every transaction.
- Backend access is protected by role-based accounts; keys are rotated regularly.
No system is perfectly secure. If you have a security concern, please email nevranizamoglu@gmail.com with "security" in the subject.
14. Third-party services
| Service | Purpose | Privacy policy |
|---|---|---|
| Apple App Store | iOS payment processing | https://www.apple.com/legal/privacy |
| Google Play | Android payment processing | https://policies.google.com/privacy |
| RevenueCat | Subscription verification | https://www.revenuecat.com/privacy |
| PocketBase | Self-hosted lookup and spam-score backend | https://pocketbase.io/docs/ |
15. Children
Kimo is intended for users 13 and over. We do not knowingly collect personal information from children. If you are a parent with a concern, please email nevranizamoglu@gmail.com.
16. Changes
If we change this policy we will update the date at the top and publish the new version at this address. Significant changes will be announced in the app and via the same email contact above.
17. Contact
Nevra Nizamoğlu — Türkiye nevranizamoglu@gmail.com
For KVKK-specific requests, write "KVKK request" in the subject line — that flags it as a formal data-subject request.